Cybersecurity Governance & GRC
Control and evidence reviews, compliance assessments, gap analysis, governance documentation and action-plan follow-up.
Andrea Lago Quijada
Senior Cybersecurity Consultant · Governance, Risk & Compliance
I connect regulation, technology risk, data and business in international, highly regulated environments.
Profile
My legal training and prior practice shaped how I interpret requirements, assess evidence and communicate with precision. I now apply that foundation to cybersecurity governance, technology risk and executive reporting.
Alongside my consulting career, I develop independent digital and business initiatives, working from proposition and positioning through to functional website delivery and operating-model design. This practical perspective complements how I work across business, governance and technical teams: bringing structure to complexity and turning information into action.
Expertise
Control and evidence reviews, compliance assessments, gap analysis, governance documentation and action-plan follow-up.
KPI and KRI monitoring and analysis, deviation management, accountability and traceability across service-governance processes.
Analysis of 100+ risk indicators, functional dashboard review, data-quality follow-up and executive communication.
Legal advice, case preparation, regulatory research and drafting, with a practical understanding of how requirements translate into controls, evidence and governance.
Developing independent digital initiatives from value proposition and service design to brand positioning, functional website delivery and practical operating models.
Complementary capabilities: applied AI and automation · project and team management · stakeholder coordination · executive communication · legal technology · SEO fundamentals
Professional examples are anonymised and limited to non-confidential information. Independent initiatives are presented at capability level.
Experience
Deloitte
Governance, technology risk, executive reporting and cross-functional coordination within an international, highly regulated financial environment.
Deloitte
Risk and service indicators, deviation analysis, data quality, functional dashboard review, compliance initiatives and coordination with distributed technical and business teams.
Distrito de Abogados
Legal advice, regulatory analysis, drafting of legal documentation and preparation and follow-up of proceedings.
LAL Abogados · Criminal & Civil Department
Legal research, documentary analysis and support in the preparation of criminal and civil matters.
INTER PARTES S.L. · Silvia Requena Abogados
Early legal-practice experience focused on research, documentary review and case preparation.
How I work
Across cybersecurity consulting, legal work and independent initiatives, I bring structure to ambiguity and maintain a clear line from analysis to action and decision-making.
Knowledge
Professional experience: SWIFT CSP
Assessment exposure: ISO 27001 · NIS2
Professional exposure: ENS · NIST
Working knowledge & training: GDPR · Spanish LOPDGDD · DORA · EU AI Act · ISO 27002 · ISO 31000
Tools: Power BI and Qlik functional user · ServiceNow professional functional use · Excel · PowerPoint · Microsoft 365 · CMDB environments functional consultation
Digital capabilities: applied AI and automation · functional web design and delivery · digital and business development · brand positioning · SEO fundamentals
Career direction
I am particularly interested in remote-first and international roles across Cybersecurity Governance, Information Security GRC, Technology Risk and Security Compliance.